Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
A maximum-severity zero-day vulnerability in Metabase's business intelligence software is being actively exploited, allowing unauthenticated remote attackers to gain administrator access.
Intelligence analysis by Gemini 2.5 Flash

Metabase has issued a warning about a critical zero-day flaw (CVSS 10.0) that enables unauthenticated SQL injection, leading to full admin control over instances. This allows attackers to alter configurations, steal credentials, and access sensitive data, with Metabase Cloud instances already updated and self-hosted users urged to patch immediately.
Imagine a special computer program that helps grown-ups look at lots of information, like sales numbers or customer lists. A sneaky trick, called a 'zero-day' because nobody knew about it until now, lets bad guys pretend to be the boss of this program without needing a password. Once they're the 'boss,' they can peek at all the secret information, change how the program works, or even steal important details about customers, like their names and emails. It's like someone finding a secret master key to a building that everyone thought was super secure.
Analysis
The discovery and active exploitation of a zero-day vulnerability in Metabase's business intelligence platform underscore the persistent and evolving threat landscape facing organizations. This particular flaw, rated with a maximum CVSS score of 10.0, is exceptionally dangerous because it allows an unauthenticated remote attacker to achieve full administrator access through SQL injection. Such a high-severity vulnerability, especially one exploited in the wild before a public CVE identifier was assigned, represents a significant challenge for defenders who must react swiftly to protect their systems.
Metabase Cloud
Metabase's proactive response to the zero-day, particularly concerning its cloud offerings, demonstrates a critical aspect of modern cybersecurity incident management. The company confirmed that its Metabase Cloud instances were attacked using this unknown vulnerability, but importantly, these instances have already been updated to the latest secure versions. This rapid patching for cloud-hosted services is a significant advantage, as it automatically protects a segment of their user base without requiring direct action from individual customers. However, the incident still serves as a stark reminder that even managed services are not immune to sophisticated zero-day attacks, necessitating continuous vigilance and robust security practices from providers.
Framework
The impact of this zero-day is concretely illustrated by the compromise of Framework, a PC manufacturer. According to reports, Framework alerted its customers that personal data, including names, login IPs, addresses, phone numbers, and emails, was accessed during the hack. While Framework noted that no order or payment information was compromised, the breach of personal identifiable information (PII) is still a serious concern, potentially leading to phishing attacks or identity theft for affected individuals. This incident highlights how a vulnerability in a third-party tool like Metabase can have direct and far-reaching consequences for an organization's customers, emphasizing the interconnectedness of supply chain security.
CVE-2023-38646
This current zero-day is not Metabase's first encounter with a critical security flaw. Exactly three years prior, Metabase addressed another "extremely severe" vulnerability, CVE-2023-38646, which carried a CVSS score of 9.8. That flaw could have led to pre-authenticated remote code execution on affected installations, demonstrating a recurring pattern of high-impact security issues within the software. The recurrence of such severe vulnerabilities suggests a need for continuous improvement in Metabase's secure development lifecycle and security auditing processes. For users, it reinforces the importance of maintaining a rigorous patching schedule and staying informed about security advisories from all software vendors.
Key points
- A maximum-severity zero-day vulnerability (CVSS 10.0) in Metabase is being actively exploited in the wild.
- The flaw allows unauthenticated remote attackers to inject SQL and gain administrator access to Metabase instances.
- Compromised instances enable attackers to change configurations, steal database credentials, and access connected data.
- Metabase Cloud instances have been updated; self-hosted users must apply patches immediately (versions x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, x.63.5).
- PC maker Framework was affected, with customer names, login IPs, addresses, phone numbers, and emails accessed.
- Indicators of Compromise (IoCs) involve specific POST and GET requests to Metabase API endpoints.
Metabase has swiftly released patches for the vulnerability, and its cloud instances have already been updated, mitigating immediate risks for a significant portion of its user base. The provision of clear indicators of compromise and temporary workarounds empowers self-hosted users to quickly identify and address potential breaches, limiting the overall impact of the zero-day.
Despite the available patches, self-hosted Metabase users who delay applying updates remain highly vulnerable to exploitation, potentially leading to widespread data breaches and unauthorized access. Attackers who have already gained administrator access could leverage stolen credentials to pivot to other systems, escalating the initial compromise into more severe and prolonged security incidents.



